
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-16-2024 05:32 PM
We would like to ingest Lansweeper internal audit logs (e.g. https://community.lansweeper.com/t5/reporting/track-lansweeper-classic-logins-and-setting-changes/ta...) in a SIEM.
Which options do we have to retrieve the logs?
a. Directly query the database for any new entries?
b. Have the logs frequently written to disk somehow and monitor those log files (e.g. via Report -> CSV)?
c. Any other ways?
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-18-2024 12:49 AM
Hi Charly,
Currently it is not possible to connect s SIEM to the on-prem version on Lansweeper, however we do offer some Intergrations with some SIEMS in our Cloud offering.
https://community.lansweeper.com/t5/cloud/introduction-to-lansweeper-cloud/ta-p/64515
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-18-2024 05:53 AM - edited 10-18-2024 05:54 AM
@Charly wrote:a. Directly query the database for any new entries?
Yes, you can!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-18-2024 05:53 AM - edited 10-18-2024 05:54 AM
@Charly wrote:a. Directly query the database for any new entries?
Yes, you can!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-18-2024 12:49 AM
Hi Charly,
Currently it is not possible to connect s SIEM to the on-prem version on Lansweeper, however we do offer some Intergrations with some SIEMS in our Cloud offering.
https://community.lansweeper.com/t5/cloud/introduction-to-lansweeper-cloud/ta-p/64515

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-19-2024 09:28 PM
That's only providing Asset information / Lansweeper content logs, but not the internal audit logs. At least that's as far as I understand the API that is the backbone for these siem apps.
